Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. Denying facts to make reality fit the collective delusion is a time honoured strategic management technique. I benefit from / perpetrate some delusions myself, so honestly no criticism.
  2. We have a serverless CCTV system, but you wont be able to buy it or any replacement components after November so I shall not be naming names. Our CCTV system consumes about 720MBit/s. How do we manage it? Well the cameras write out to "appliances" clustered around the site. Not servers. Nope. It's serverless you see. (seriously, that was basically the pitch) I'm not sure a true "serverless" solution is viable once you start to have more than a couple of dozen cameras, and you have a requirement to keep footage for more than a day or two, even if you only record on motion and each camera writes to its own local storage.
  3. Consider adjusting power management so your devices are able to power up and run their maintenance tasks (including Updates) overnight. You should check your GPOs, Collection Settings and Intune policies and then choose one point of truth (de-configuring the others taking into account @gybe78's advice). When I say one point of truth... I mean one point of truth for Pure AD/SCCM and Hybrid AAD Joined/Co-Managed, and (potentially but not necessarily) another for Pure AAD/Intune devices. If your firewall is collapsing under the load, and it is not saturating your uplink to your ISP then I would definitely look to resolving that limitation - it could be a config tweak there and all these problems go away... or it could be you need to build a case to get a bigger firewall to support the cloud-based future.
  4. We've had oddness when accounts have fallen out of scope of AAD Sync and then fallen back in scope seemingly causing 3rd party systems syncing with on prem AD to start preferring the X500 address for those users. It probably has something to do with adding/removing exchange licenses on mail enabled accounts.
  5. I suspect that message is really aimed at those who have their money in Montagu Private Equity.
  6. psydii

    KB5034441

    Is this not the update that allows the recovery tools to continue to work after Microsoft switch on the previously installed bitlocker-bypass-vulnerabilty fix in a few month time? I seem to recall that MS are working on a better way to get the RE partition updated (but that was from an anon in a forum who claimed to have an open ticket about it), if true, I'd imagine it will either be in WSUS, in a standard monthly update, or there will be an easy automatable way to resize the partitions magically added to Windows.
  7. Its been a long time since I looked at what the market can offer in this regard. We do a variation on the below and have done for 14 years. 1) require pupils to register their device mac address with you. (randomised mac addresses must be disabled) 2) A subnet per year group (at least). Each with a scope configured with "reservations" only, each registered device gets a reservation in the appropriate scope. 3) radius auth based on username. your can then drop pupils into correct subnets based on their group membership. 4) On the filtering platform, filter rules based on subnet rather than user/group. You might want additional subnets available for cases where additional restrictions need to be applied (as a sanction, or for special projects) You now can map ip to users, and have some granularity on the control of access to services. If you don't mind cross referencing several sources when doing and investigation, you can skip the MAC address/DHCP reservation part. This is basically how we do things. If I need to trace a device back to a user I have to go splunking in NPS logs / DHCP logs to see who has that address. With regard to RADIUS/TLS being a headache - generally only once or twice per pupil every three or so years. How to get through the logon screens correctly is the sort of knowledge that spreads thorough a student body on its own. If you have TLS MITM inspection or intend to, then your might as well stand up your own CA to serve radius and the firewall/proxy and have them import those root cert.
  8. Having participated in migration from RMNET3 ->RM Lan Manager->Connect 1 ->Connect 2, we went vanilla for the roll out of Windows 2000. We also used their RM IfL service from almost day one (prior to that, my first email address was a bit of a kludge via the RM BBS!) I think it was only a decade or so ago that the dns records from our dialup connection were purged. IfL was one of the biggest ISPs in the world, and was at the cutting edge of proxy/filtering fin the nineties. I was very surprised they didn't become one of the global leaders in that space. That said, I've not used them since 2002.
  9. There are standards to which buildings are constructed to avoid requiring that sort of regular inspection. However sometime faults are identified and then an inspection regime is put in place. Also some things in a building are on an inspection regime from day one. (Though through changes in management these regimes seem to get forgotten over time in time something somewhere breaks and people get hurt). If you know something is not ideally put together or approaching/past the point when it should have been replaced, and its failure poses a danger, it should be inspected periodically to reduce the risk of harm. We inspect our screens every half term. Not for safety but to ensure there hasn’t been any configuration drift (caused by teach/technician quick bodges that may have accumulated over the term). I’m minded to add check the bolts stability even though all of our installs have been done by professionals who made a point for checking the M&E/asbestos records for all surfaces to which they were securing the kit. Shouldn’t be necessary, but I’ve been that kid who absentmindedly twiddle bolts/ removed terminators when bored.
  10. I've not looked into Print Deploy in much detail, however I got both strong application repackaging vibes, which many of us may have forgotten (or never needed to learn in the first place), and woah! old-school (circa 2000) Windows Printer behaviours. What I suspect is happening is that a during the printer capture process the offending account is interacting with the computer on which the printers are being packaged. This account probably has "manage this printer" rights on the printer object on the server, and is somehow tattooed into the deployment package. Then during the deployment phase on a target workstation, the local printer object (settings and drivers etc) are deployed, there is some back and forth of settings (old-school: settings changes to a local instance of a server-shared-printer used to (sometimes?) write those settings back to the server) and since the deploying printer on the local machine is set "not shared" it writes that back to the server! It has been years since I last saw client side changes writing back to the server - I'd assumed this behaviour was blocked. I know that the windows team are working hard to rebuild the print system, perhaps they have accidentally re-introduced the code path where this sort of thing can happen? It may be that the offending account is not involved in the initial printer capture process - It might just be enough that the user has manage this printer rights on the server instance. It may also be that due to a regression this permission isn't even required!
  11. Yes You need to redesign the staff share and compartmentalise it into discreet Teams/Sites. This is absolutely one of those times where the technical people need to change the way the organisation works - and this requires close working with the key stakeholders to create a new way of working that is acceptable to all. They key drivers are data protection and business continuity, work with your DPO and a Dep Head/Business manager to lead it from this angle. To restate how *we* do it: We have a site/team for each department, which limits the scope of potential damage. We have several communication sites for sharing documents read only with all staff (HR, Safe Guarding, IT Helpdesk, general school documents and stuff). Owners of the information are the Owners of these sites, All Staff are visitors. The PA / Office Manager / Business manager owns the general school documents site, and manages access therein at a folder level. When a document needs to be shared outside of the owners/members group of the site, then it is done limited to the specific file/folder to a suitable azuread/local ad group. Mostly these documents are transitory and end up being shared directly from the member of staff who needs to collect the data's OneDrive. This (and a similar set up for on premises folders) has limited the impact of accidental moves/deletes multiple times in the last 24 years. FWIW that AD role/capability group design is a derivation of a method published in the Windows 2008 Resource kit book Productivity Solutions for IT Professionals by Dan Holme*. Dan went on to join the SharePoint team when they were remodelling SharePoint into the modern teams-centric (Owner, Members, Visitors) security model we see today. *actually Dan's book was a pulling together of best practice that started with the 1996 Paper https://csrc.nist.gov/CSRC/media/Projects/Role-Based-Access-Control/documents/sandhu96.pdf and the 1997 NT-centric follow up https://dl.acm.org/doi/pdf/10.1145/266741.266769
  12. We use Netgear smart parental controls, its no smoothwall, but it does "ok". It drops hints from time to time that it is based on Circle. Its a paid service - I don't want to spend any more time than necessary troubleshooting computers at home - I scratch that itch all day long at work! They also have an app that can install onto devices that adds another layer of capability, but we haven't (yet) needed to go down that route. Most of the apple Privacy stuff has to be disabled too. (coz its basically a VPN). Sometimes on Windows PCs Chrome punches through the filter to allow youtube though this seems to have recently been either fixed by NG/Circle or Google saw reason and stopped using tunnelling (aka vpns) to evade network level youtube filtering. I do wish though the exception rules exposed a little more functionality and had a few more pre-made applications allow/block rules; 'always' allowing google classroom was a pain to set up by hand - have you looked at the allow list for drive?!
  13. How did you first try to disable it? Last time I had to, I used this command, which I seem to recall did what was needed: https://learn.microsoft.com/en-us/powershell/module/exchange/disable-distributiongroup?view=exchange-ps
  14. I'm fighting a similar problem right now. Some (but not all?!) devices will randomly decide to believe they are US based, and often mess up time and the autopilot process. We've got a similar policy as you that fixes any laptop that did manage to get through into a managed state with the regional settings wrong. There doesn't seem to be rhyme or reason to it - seen it in laptops that we manually added to autopilot during oobe, and devices configured by the reseller. Most are fine, but some go weird. So so so strange.
  15. Some wireless professionals used to do bake-offs between vendor kit using dozens/hundreds of clients and a handful of aps. These always showed traffic throughput tending to 1Mb/s once the channel gets busy servicing more than a handful of clients simultaneously. *However* most of the time devices are not all trying to throw hundreds of megabytes around at the same time, so the increased capacity on a channel through the later technological developments (beamforming and SU-MIMO, MU-MIMO, very High QAM, Color etc) should/might make a huge difference moment by moment, thus modern wifi might not ever feel slow, even though under stress it probably collapses as it has ever done. I have done a bake off with wave2 ac - not to the standard I could publish it (if i could even still find the data) - the most significant improvement was 4x4 vs 2x2 - we could see 4x4 APs (well, their cli reported that they were) servicing multiple 1x1 and 2x2 clients simultaneously, while the 2x2 APs were not able to. This was reflected in the 4x4 throughput under load (120 clients / 3 APs / 6 rooms) - still down at less than 5Mb/s but better than the 1-2Mb/s of the 2x2 kit under heavy load. Extrapolating (even less scientifically than my bake-off) I would make the prediction that with a well designed RF environment and Wifi 7 you might see three to four times the OVERALL throughput underload - and that would still only be 15-20Mb/s. Lightly loaded you might get closer to 1Gb/s on any given client at the moment - but I've not seen Google Drive, or Onedrive/Sharepoint ever serve/accept files at even close to that speed so I'm not sure (for those who *might* be able to afford it) spending money recableing and upgrading switches to 2.5G /10G for modern APs is worth it. Obviously if you are getting external funding take the best you can, we're still riding on the CAT6/OM3/10Gb backbone brought in from BSF 15 years ago. But I find the lack of comparative hard data on modern wifi kit quite telling. To return to the original question though: I like core infrastructure to be supported and our APs fall out of support in a couple of years - its on our roadmap the Finance Director financial projections include its replacement.
  16. To be honest the conversation was brief and I only went there because I knew that their background meant they'd "get it" quickly and they would have a sense of learning something their peers wouldn't understand. That little bit of knowledge helped smooth over the "well this is fast to do this, but slow to do that" conversations. I've been lucky that most of my Heads have had Science/Maths/Medical PhDs and/or MBAs. A couple had even been quite competent Network Managers!
  17. That I think was the original philosophy in the Bromcom MIS. I can't speak to how things are now, but I know that some customers did not really get on board with that. It required (for those customers) too great a shift in mental model on how things work. - try explaining Normalization to a Head teacher. (actually I had success with that once - they had a postgrad degree in something adjacent to set theory, but the except makes the rule eh?) It also somewhat is counter to how cloud scale databases work - where normalization more readily comes at too high a cost to performance. The final point against it is that you need to see what the letter/report actually said not what it would say if you were to run it today.
  18. Long ago (on prem, but around the transition to cloud-only), I'm pretty sure we had attached documents as blobs outside the database. In the same timeframe, I also seem to recall that the 'bromcom way' (which differed greatly from the two dominant providers at the time, SIMS and CMIS) was that documents in the traditional sense should not be generated, and the feature to store them was almost added under duress. The cloud pricing reflected this - it was to "encourage" adopting the workflows as designed. But that was so far in the past in cloud terms, I might as well be talking about winfolder.
  19. I would expect that a few on here are MAT Directors of IT and higher, and it's also not an unreasonable salary for a Deputy Head. FWIW a salary like that is currently one of my goals.
  20. The ink on the NI contract is barely dry, so I wouldn't expect it to appear on any dashboards yet, as any existing customers are almost certainly running out of the existing datacentres. Moving forward if its contractually allowable, I'd expect the NI provision to run out of the datacentres south of the border, and have zero impact on system performance. Staffing of course is another matter entirely - but as observed earlier in this thread, they are hiring.
  21. I was hoping someone might jump in by now with a solution. However they have not. If you can post a link to the script/article I might be able to parse it and see if anything jumps out. However - I wonder if you are falling between two stools here. We moved folders to OneDrive and Sharepoint BEFORE we moved to Intune. The "obvious" solution is to adjust peoples working practice and have the folders on SharePoint/Teams (ideally segregated by department - but this depends on size/phase of school, and potentially whether we're talking single school or MAT), which they access via the web or the OneDrive client. To spend time mapping drives to legacy network shares via Intune on a pure-Intune managed device seems like investing further in a dead-end. Personally I do not believe ODM is the correct approach either, but many would disagree with me - and I haven't really looked into it. smb network shares are a legacy we need to take a step away from at every opportunity.
  22. I’ll bite. Why on earth would you want to restrict who can execute dwm? (Which is what an explicit/specific allow for admin rule implies) Also I think dwm might be one of those processes that in some circumstances is started by the system before changing its context to the current user, which (if I am right) would be why it didn’t work - logon via RDP can make things weirder than usual.
  23. But they do for some (a number of our parents reported individual breaches to us and we reported them to classcharts). It would be prudent to presume the number of individuals whose data has been breached is equal to the number of parents polling the system in the "15 minute" window. This is a figure unknown to us on the outside, but based on anecdata a reasonable guess would be less than 5 breaches per 2000 students.
  24. When cold-starting a system (particularly if you are unfamiliar with it), generally start from the lowest point/core and work your way up/out. With networking, that typically would be the switch stack that is connected to servers / firewall and all the other switches. Then bring up the DHCP and DNS Servers. Then bring up the network management platform, then bring up the rest of the switches working outwards from the core. If any of the core has PoE or the edge is started before the core, you may find devices connected to these ports have started before the necessary network services (DHCP/DNS/Management plane) so you might need to power cycle them again. For some wireless systems, restarting while the switched network has not fully started will result in them going into a wireless mesh, or split brain (where some are in one management domain and some are in another), or worse they start doing very odd things with trunked ports and get their switch ports shutdown by Spanning Tree. Disabling PoE for the wireless switch ports (but not saving the config), then rebooting the edge switch (which clears spanning tree decisions and reloads the last saved config) will usually clear the problem. We have the extra fun problem that there are still inline power injectors for some devices, so we can't easily cut power, and they get properly grumpy if the switch isn't up for a few minutes, we have to go messing around in cabinets and ceiling voids to bring these back on line.
  25. These two points *really* get my goat every time I think about it. Luckily being over-worked and understaffed I don't have time to ruminate on it often. And before I start now, I'm off to play Baldur's Gate which cost 2x my allocated A5 licence, and yet I only use a few hours a week.
×
×
  • Create New...